NEW: Group Profiler — instant APT intel lookup. Try it →

TA459

G0062 China MITRE ATT&CK →

Overview

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.

Naming & attribution

TA459 is tracked under 1 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
TA459Axel F

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 5 techniques across 2 tactics

Initial Access

Execution

Tools & malware (4)

gh0st RAT · NetTraveler · PlugX · ZeroT

Reporting (1)